EIN: 146012314
UEI: VFW3KAT2NVJ3
Audited by: Bonadio & Co., LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 31, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on April 1, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2026 (30 days from today).
What is a management decision? →FAC accepted this audit on March 6, 2025 — management decision was due September 6, 2025.
FAC accepted this audit on May 3, 2024 — management decision was due November 3, 2024.
During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program. An annual IT risk assessment was not performed. A vendor management program is not in place. Mobile device management is not in place. Backup media is not encrypted. A full set of policies and procedures is not in place. Finding Reference: 2023-001 (Continued) U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Compliance Requirement: Special Tests and Provisions Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates.
Show full finding ▾Hide full finding ▴Finding Reference: 2023-001 U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Nursing Student Loans (Assistance Listing #93.364) Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires the College, on an annual basis, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer (student) information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, the GLBA risk assessment should include consideration of risk in each relevant area of operations, including: Employee training and management. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. Detecting, preventing, and responding to attacks, intrusions, or other system failures. Condition: During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program. An annual IT risk assessment was not performed. A vendor management program is not in place. Mobile device management is not in place. Backup media is not encrypted. A full set of policies and procedures is not in place. Finding Reference: 2023-001 (Continued) U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Compliance Requirement: Special Tests and Provisions Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates.
CORRECTIVE ACTION PLAN Federal Award Findings and Questioned Costs Finding 2023-001 Student Financial Aid Cluster: Assistance Listing #84.007 Federal Supplemental Educational Opportunity Grants Assistance Listing #84.033 Federal Work-Study Program Assistance Listing #84.063 Federal Pell Grant Program Assistance Listing #84.268 Federal Direct Student Loans Assistance Listing #93.364 Nursing Student Loans Federal agency – U.S. Department of Education Grant Period – Year ended August 31, 2023 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires the College, on an annual basis, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer (student) information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, the GLBA risk assessment should include consideration of risk in each relevant area of operations, including: Employee training and management. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. Detecting, preventing, and responding to attacks, intrusions, or other system failures. Condition: During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program. An annual IT risk assessment was not performed. A vendor management program is not in place. Mobile device management is not in place. Backup media is not encrypted. A full set of policies and procedures is not in place. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Donna Rocap, Associate Vice President of Administration Corrective Action Plan: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates. Timing of Planned Corrective Action: The College expects to resolve this finding during its August 31, 2024 fiscal year.
FAC accepted this audit on April 30, 2023 — management decision was due October 30, 2023.
FAC accepted this audit on May 22, 2022 — management decision was due November 22, 2022.
FAC accepted this audit on May 27, 2021 — management decision was due November 27, 2021.
The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.
Show full finding ▾Hide full finding ▴Finding 2019-001 (Repeat Finding) Student Financial Aid Cluster ? CFDA Numbers - 84.007, 84.033, 84.063, 84.268 Federal Agency ? U.S. Department of Education; Grant Period ? Year ended August 31, 2020; Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.
U.S. Department of Education Student Financial Aid Cluster: CFDA 84.007 Federal Supplemental Educational Opportunity Grants CFDA 84.033 Federal Work-Study Program CFDA 84.063 Federal Pell Grant CFDA 84.268 Federal Direct Student Loans Federal agency ? U.S. Department of Education Grant Period ? Year ended August 31, 2020 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition and Effect: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Provost View of responsible officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.
2019-001
FAC accepted this audit on May 25, 2020 — management decision was due November 25, 2020.
The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to require several months to complete.
Show full finding ▾Hide full finding ▴Finding 2019-001 Student Financial Aid Cluster ? CFDA Numbers - 84.007, 84.033, 84.063, 84.268; Federal Agency ? U.S. Department of Education; Grant Period ? Year ended August 31, 2019; Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to require several months to complete.
Student Financial Aid Cluster: CFDA 84.007 Federal Supplemental Educational Opportunity Grants CFDA 84.033 Federal Work-Study Program CFDA 84.063 Federal Pell Grant CFDA 84.268 Federal Direct Student Loans Federal agency ? U.S. Department of Education Grant Period ? Year ended August 31, 2019 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition and Effect: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Provost View of responsible officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to be completed by August 31, 2020.
FAC accepted this audit on February 27, 2019 — management decision was due August 27, 2019.
FAC accepted this audit on March 4, 2018 — management decision was due September 4, 2018.
FAC accepted this audit on March 15, 2017 — management decision was due September 15, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in New York →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.